US2019014137A1PendingUtilityA1
IoT DEVICE SECURITY
Est. expiryJul 10, 2037(~11 yrs left)· nominal 20-yr term from priority
G06N 3/042H04L 63/20G06F 21/554H04L 67/10H04L 63/1425H04L 63/0272G06N 3/08G06F 17/30598G06N 3/0427G06F 17/30374G06N 3/0499G06N 3/09G06F 16/2372G06F 16/285
37
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Techniques for providing Internet of Things (IoT) device security are disclosed. An applicable system includes IoT devices coupled to an evolving context-aware IoT device security system. In a specific implementation, the system uses common factor aggregation of event parameters to determine IoT device personality.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . A method comprising:
performing common factor aggregation of enriched metadata derived from event parameters to obtain aggregated metadata permutations; obtaining domain knowledge, including knowledge regarding bad IoT personalities, from a network administration engine; defining a personality, including data samples associated with the personality, using the aggregated metadata permutations, the domain knowledge, and prior personality data set feedback from a new personality profile discovery engine; classifying the personality using the data samples and IoT personality models, wherein the personality has a signal associated therewith; correlating the signal to reach a verdict and, if the personality is a bad personality, providing bad personality feedback associated with the personality to the network administration engine; discovering, at the new personality profile discovery engine, new personality data set feedback from the classified personality and the verdict.
2 . The method of claim 1 , wherein the personality is built by mathematically modeling a behavior pattern using the event parameters.
3 . The method of claim 1 , comprising enriching raw metadata to obtain the enriched metadata.
4 . The method of claim 1 , wherein the aggregated metadata permutations are part of a common methodological framework of IoT device demographics.
5 . The method of claim 1 , wherein the aggregated metadata permutations are aggregated over a data rollup window that varies based on the context of the IoT device.
6 . The method of claim 1 , comprising:
performing offline modeling using the data samples; updating the IoT personality models with the offline modeling.
7 . The method of claim 1 , wherein the data samples are first data samples, comprising:
performing offline modeling using second data samples; classifying the personality using the first data samples, the second data samples, and the IoT personality models.
8 . The method of claim 1 , comprising: recognizing behavior patterns of the IoT device using either or both learned state-transition learning and deep learning.
9 . The method of claim 1 , comprising: recognizing behavior patterns of the IoT device using either or both a neural network graph of past behavior patterns of the IoT device recognized using deep learning and a state transition graph of the past behavior patterns of the IoT device recognized using learned state-transition learning.
10 . The method of claim 1 , comprising:
computing a degree of risk of undesirable behavior; generating the bad personality alert if the degree of risk of undesirable behavior exceeds an actionable intelligence threshold.
11 . The method of claim 1 , wherein at least some of the domain knowledge comes from at least one of security research and human expertise, comprising: using the new personality set feedback to enhance IoT personality models and create new personality models that describe bad behaviors.
12 . A system comprising:
a network administration engine; a domain knowledge datastore, coupled to the network administration engine, that stores domain knowledge, including knowledge regarding bad IoT personalities received from the network administration engine; an IoT device demographics generation engine configured to perform common factor aggregation of enriched metadata derived from event parameters to obtain aggregated metadata permutations; an IoT personality definition engine, coupled to the IoT device demographics generation engine and the domain knowledge datastore, configured to define a personality, including data samples associated with the personality, using the aggregated metadata permutations, the domain knowledge, and prior personality data set feedback; an IoT personality datastore, coupled to the IoT personality definition engine, that stores IoT personality models; a personality classification engine, coupled to the IoT personality definition engine and the IoT personality datastore, configured to classify the personality using the data samples and IoT personality models, wherein the personality has a signal associated therewith; a signal correlation engine, coupled to the personality classification engine, configured to correlate the signal to reach a verdict and, if the personality is a bad personality, provide bad personality feedback associated with the personality to the network administration engine; a new personality profile discovery engine, coupled to the personality classification engine and the signal correlation engine, configured to discover new personality data set feedback from the classified personality and the verdict for provisioning to the IoT personality definition engine.
13 . The system of claim 12 , wherein the personality is built by mathematically modeling a behavior pattern using the event parameters.
14 . The system of claim 12 , comprising a personality aware enrichment engine, coupled to the IoT device demographics engine, configured to enrich raw metadata to obtain the enriched metadata.
15 . The system of claim 12 , wherein the aggregated metadata permutations are part of a common methodological framework of IoT device demographics.
16 . The system of claim 12 , wherein the aggregated metadata permutations are aggregated over a data rollup window that varies based on the context of the IoT device.
17 . The system of claim 12 , comprising an offline modeling engine, coupled to the IoT personality definition engine and the IoT personality datastore, configured to:
perform offline modeling using the data samples; update the IoT personality datastore with models in conformity with the offline modeling.
18 . The system of claim 12 , wherein the data samples are first data samples, comprising an offline modeling engine, coupled to the IoT personality definition engine and the IoT personality datastore, configured to:
perform offline modeling using second data samples; update the IoT personality datastore with models in conformity with the offline modeling.
19 . The system of claim 12 , wherein the IoT device demographics generation engine uses either or both learned state-transition learning and deep learning.
20 . The system of claim 12 , wherein the IoT device demographics generation engine uses either or both a neural network graph of past behavior patterns of the IoT device recognized using deep learning and a state transition graph of the past behavior patterns of the IoT device recognized using learned state-transition learning.
21 . The system of claim 12 , wherein the signal correlation engine is configured to:
compute a degree of risk of undesirable behavior; generate the bad personality alert if the degree of risk of undesirable behavior exceeds an actionable intelligence threshold.
22 . The system of claim 12 , wherein at least some of the domain knowledge comes from at least one of security research and human expertise, wherein the IoT personality definition engine uses the new personality set feedback to enhance IoT personality models and create new personality models that describe bad behaviors.
23 . A system comprising:
means for performing common factor aggregation of enriched metadata derived from event parameters to obtain aggregated metadata permutations; means for obtaining domain knowledge, including knowledge regarding bad IoT personalities, from a network administration engine; means for defining a personality, including data samples associated with the personality, using the aggregated metadata permutations, the domain knowledge, and prior personality data set feedback from a new personality profile discovery engine; means for classifying the personality using the data samples and IoT personality models, wherein the personality has a signal associated therewith; means for correlating the signal to reach a verdict and, if the personality is a bad personality, providing bad personality feedback associated with the personality to the network administration engine; means for discovering, at the new personality profile discovery engine, new personality data set feedback from the classified personality and the verdict.Join the waitlist — get patent alerts
Track US2019014137A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.